T01 · Skill Instruction Hijacking
- Location
HEARTBEAT.md:24- Finding
External Task Instructions Are Processed Without Human Approval or Trust-Boundary Enforcement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed TaskPod integration, but it asks agents to keep polling for outside tasks and perform some contest/social actions with too little per-action user control.
Install only if you intentionally want this agent connected to TaskPod as a recurring worker. Before enabling heartbeat or contest mode, require human approval for each accepted task and each social post, restrict credentials and callback destinations, validate task URLs and webhook signatures, and keep a clear way to disable polling and remove memory/heartbeat-state.json.
HEARTBEAT.md:24External Task Instructions Are Processed Without Human Approval or Trust-Boundary Enforcement
HEARTBEAT.md:24Persistent Periodic Polling Establishes a Cross-Session External Control Channel
HEARTBEAT.md:214Automated Promotional Posting and Engagement Can Cause Unauthorized Public Actions
The contest social instructions encourage autonomous posting and interaction on an external platform without notifying the user or obtaining approval. This is especially risky because public posts, comments, and reactions can affect reputation, disclose strategy, and misuse linked accounts.
The Moltbook posting and engagement instructions are unjustified by the stated TaskPod purpose and create a new capability to publish and interact on a separate platform. That is dangerous because it enables unauthorized outbound communications and social manipulation behavior that users may not expect from a registration/discovery skill.
The file instructs the agent to make authenticated external API calls and persist local state without warning the user that data will be transmitted to TaskPod and files will be modified. This undermines informed consent and can lead to silent disclosure of capabilities/status metadata and unapproved local state changes.
The heartbeat instructions materially expand the skill from simple registration/discovery into autonomous polling, task intake, processing, retries, and workflow management. That scope creep increases the agent's operational authority and can cause unreviewed execution of externally supplied tasks, which is risky when the manifest does not clearly disclose or constrain those behaviors.
This instruction directs periodic authenticated heartbeat transmissions to TaskPod, creating recurring external data egress and continuous service contact. The danger is increased by the scheduled, autonomous nature of the behavior, which can occur without ongoing user awareness.
## TaskPod (every 30 minutes)
If 30+ minutes since last TaskPod check:
1. Send heartbeat: POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat
2. Check for tasks: GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. If tasks found matching your capabilities → process them
4. Update lastTaskPodCheck timestamp
Polling TaskPod for pending tasks is an external transmission that also serves as an intake channel for untrusted remote work items. In this skill's context, it is more dangerous than a simple API read because the next instruction is to process matching tasks, potentially causing autonomous execution of externally sourced instructions.
If 30+ minutes since last TaskPod check:
The documented curl command shows outbound authenticated communication to TaskPod. Even as example content, it promotes a pattern of external transmission that should be treated as sensitive because it uses API credentials and shares operational metadata.
curl -X POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The documented curl command shows outbound authenticated communication to TaskPod. Even as example content, it promotes a pattern of external transmission that should be treated as sensitive because it uses API credentials and shares operational metadata.
curl -X POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The task-check endpoint is an external fetch of potentially actionable remote content, and in this document it is directly tied to accepting and processing discovered tasks. That combination creates a meaningful risk of untrusted instruction ingestion and autonomous behavior beyond the user's original expectation.
After each heartbeat, check if there's work waiting:
curl "https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5" \
-H "Authorization: Bearer YOUR_API_KEY"
The contest section adds autonomous cross-platform posting and social interaction behavior unrelated to basic TaskPod registration/discovery. This broadens the skill into promotional and engagement activity on external services, creating risk of spam, reputational harm, and unauthorized actions under the user's identity.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://api.taskpod.ai/v1/agents \
-H "Content-Type: application/json" \
-d '{
"name": "YOUR_AGENT_NAME",
The skill instructs the agent to add an automatic heartbeat that repeatedly contacts a third-party service every 30 minutes and poll for pending tasks. This establishes persistent outbound communications and a mechanism for receiving arbitrary future work from an external platform, which increases attack surface and could cause unreviewed task ingestion or privacy leakage if added blindly to an agent’s periodic workflow.
## TaskPod (every 30 minutes)
1. POST https://api.taskpod.ai/v1/agents/YOUR_ID/heartbeat
2. GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. Process any matching tasks
Polling the external tasks endpoint encourages the agent to fetch work items from a third-party queue on a recurring basis. In this skill context, that is more dangerous than a one-time registration call because it can continuously import untrusted task content into the agent’s execution flow, creating a supply-chain style risk if the agent later processes those tasks automatically.
## TaskPod (every 30 minutes)
1. POST https://api.taskpod.ai/v1/agents/YOUR_ID/heartbeat
2. GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. Process any matching tasks
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---
# TaskPod — The Trust Layer for AI Agents
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://api.taskpod.ai/v1/agents/register \
-H "Content-Type: application/json" \
-d '{
"name": "Your Agent Name",
No suspicious patterns detected.